Malicious News
  • Home
  • About Us
  • Malware
  • Vulnerabilities
  • Facebook
  • Twitter

Malicious News

Malicious News
CISA Emergency Directive to Federal Agencies Regarding Ivanti Zero-Day Exploits

Vulnerabilities

CISA Emergency Directive to Federal Agencies Regarding Ivanti Zero-Day Exploits

In a recent development, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive on Friday, urging Federal Civilian Executive Branch (FCEB) agencies to implement mitigations against two actively exploited zero-day flaws found in Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) products. The vulnerabilities, namely

By Malicious News 23 Jan 2024
Admin Takeover Flaw In Synology DiskStation Manager

Vulnerabilities

Admin Takeover Flaw In Synology DiskStation Manager

A vulnerability has been identified in Synology's DiskStation Manager (DSM), capable of being exploited to uncover an administrator's password and seize control of the account remotely. According to Sharon Brizinov from Claroty's Team82 in a report on Tuesday, "Under some rare conditions, an attacker could leak enough information to restore

By Malicious News 20 Oct 2023
How to Boost Your Security with a Password Manager

General Security

How to Boost Your Security with a Password Manager

Introduction Are you tired of keeping track of all your passwords? Do you have trouble remembering which combination goes with what account? Enter the password manager. A password manager is a software program that securely stores and manages all your login information for various websites and applications. With just one

By Malicious News 26 Jun 2023
malware

malware

7 Places where malware can hide

Malware can hide in various places on a computer or network. Here are some common locations where malware may hide: 1. System files: Malware can disguise itself as legitimate system files or inject malicious code into existing files. 2. Temporary folders: Malware often uses temporary folders to hide and execute

By Malicious News 03 Jun 2023
Trojan Steals Facebook Credentials From Over 300K Android Users

malware

Trojan Steals Facebook Credentials From Over 300K Android Users

A new Android campaign called Schoolyard Bully has spread to over 300,000 Facebook users. The trojan has been found in applications downloaded from the Google Play store and third-party app stores. Schoolyard Bully disguises itself as an educational application primarily targeting Vietnamese readers. Zimperium Researchers said The trojan uses

By Malicious News 03 Dec 2022
vmware

Vulnerabilities

3 New Critical Warnings For VMware Workspace One Assist Software

VMware released security updates to fix 3 critical vulnerabilities in their One Assist Software. A malicious actor with network access may be able to obtain administrator access without the need to authenticate. Workspace One Assist is a real-time remote support software. These flaws are being tracked as CVE-2022-31685 (Authentication Bypass

By Malicious News 09 Nov 2022
OPENSSL

docker

Patches released for 2 OpenSSL High Vulnerabilities

On Nov 1st OpenSSL project has release patches for a couple of high severity flaws that could trigger Denial of Service or trigger remote code execution. Tracked as CVE-2022-3786 An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.’ character

By Malicious News 02 Nov 2022
Apple releases IOS and iPadOS patches for an actively exploited zero-day vulnerability.

Vulnerabilities

Apple releases IOS and iPadOS patches for an actively exploited zero-day vulnerability.

On Monday Apple released a patch for a zero-day flaw that’s been actively exploited. Tracking as CVE-2022-42827 described An out-of-bounds write issue was addressed with improved bounds checking. In the out-of-bounds write vulnerability, the software writes data past the end, or before the beginning, of the intended buffer, which

By Malicious News 26 Oct 2022
Emotet

malware

Emotet What Does It Do?

Emotet was once described as the “world’s most dangerous malware“, by Europol. Security researchers first discovered the malware as a banking trojan in 2014. What is Emotet? Emotet is a Trojan that is spread through email, that could contain a malicious attachment or a malicious link. Emotet utilizes social

By Malicious News 22 Oct 2022
Zimbra

Zimbra

Zimbra Exploit Added to CISA KVE

CISA on Thursday, Oct 20 added the Zimbra Collaboration exploit to the Known Vulnerabilities Exploit catalog (KVE). The issue is tracked as CVE-2022-41352, this is a remote code execution vulnerability that has to do with cpio a third-party utility tool used to extract archive attachments from an email. Which allows

By Malicious News 20 Oct 2022
Malware threat

malware

5 Most Dangerous Malware Threats

Malware is constantly changing and becoming more advanced and harmful. Cybercriminals will do whatever it takes to access a computer system and handle sensitive data. 1. Clop Ransomware One of the deadliest computer risks is clop ransomware, which may start or stop processes in a Windows domain in order to

By Malicious News 18 Oct 2022
Fortinet Feature img

Authentication

Fortinet Authentication Bypass Exploit POC Released

Horizon3.ai recently released a proof of concept on the Fortinet Authentication Bypass vulnerability. Horizon3.ai researchers created an exploit after examining the differences between the vulnerable firmware and the patched version. Soon after releasing the proof of concept, exploit attempts numbers started to rise. On Thursday Wordfence Threat analyst

By Malicious News 14 Oct 2022
See all
Malicious News
  • Privacy Policy
Powered by Ghost